The U.S. Federal Trade Commission unanimously rescinded its 2021 policy statement that asserted the FTC Health Breach Notification Rule applied to health and fitness apps, trackers, and other connected devices handling individually identifiable consumer health data. The statement had aimed to close notification and privacy gaps for products outside HIPAA’s traditional healthcare-organization scope, and contemplated enforcement actions and civil penalties for failures to report breaches or unauthorized disclosures.
The FTC said its 2024 amendments to the Health Breach Notification Rule now expressly cover health applications and connected devices, rendering the earlier guidance obsolete and of minimal additional benefit. The withdrawal also aligns with the White House deregulatory directive to eliminate unnecessary subregulatory guidance; organizations should continue to assess obligations under the updated rule rather than treating the rescission as removal of health-data breach-notification requirements.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
The FTC updated the Health Breach Notification Rule to cover health applications and connected devices, including fitness trackers. The agency later said this update made the 2021 policy statement unnecessary.
The FTC adopted a policy statement asserting that its Health Breach Notification Rule applied to health and fitness applications, trackers, and other connected devices collecting identifiable health information. The statement was adopted by a divided 3-2 vote during the Biden administration.
The FTC unanimously rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. It said the statement provided minimal benefit, had been superseded by rulemaking, and was obsolete under the updated notification rule.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.